You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Fix agent vex checking only one installed copy (#516) (#517)
* Start fix for #516
Assisted-by: Claude Code:claude-opus-5-5
* Check every installed copy before vex attests
When a project holds several installed copies of the same
package@version (npm nests duplicates, and a later install can add a
fresh unpatched one), `vex` only hashed the first copy it found. It
could then attest a patch as not_affected while another copy that a
dependent loads was still unpatched.
Agent-mode records are now attested only when every installed copy
matches the patched bytes, the same rule `apply` follows when it
patches and that hosted records already use. The vendored drift
warning also checks every copy.
Fixes#516
Assisted-by: Claude Code:claude-opus-5-5
* Document every-copy rule for agent vex records
Assisted-by: Claude Code:claude-opus-5-5
---------
Co-authored-by: Claude <noreply@anthropic.com>
Copy file name to clipboardExpand all lines: crates/socket-patch-cli/CLI_CONTRACT.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -387,7 +387,7 @@ Recognition rules that hold for every ecosystem:
387
387
|---|---|---|
388
388
| Vendored: a lockfile/config wires a `.socket/vendor` artifact, or a live vendor ledger entry | The **committed artifact** is hashed against the record's `afterHash`. The ledger entry is used when it names the wired artifact (it carries the dir-artifact inventory); otherwise an entry is synthesized from the reference. A present installed tree with different bytes only warns `vendored_tree_out_of_sync`. | `(vendored)` |
389
389
| Hosted: a discovered patch-host reference (or a live pre-v5 redirect-ledger record) | The installed copies the build **consumes** through the hosted wiring are hash-verified when any exist: the Go replacement module, never the pristine `M@v` in the module cache; the Socket-registry cargo source dir; maven's suffixed version. Installed evidence wins: `hash_mismatch` / `not_applied` are omitted. With **nothing installed**, a discovered reference whose lock pins the artifact (or whose format's rewriter never writes a pin) attests from that pin, which is the same evidence as in-run `scan --mode hosted --vex`. A pre-v5 ledger-only record, or a reference whose required pin is missing, stays `package_not_found`. So do purls that `--ecosystems` kept out of the crawl, because "not installed" has to mean the crawler looked. | `(redirected)` |
390
-
| Agent: a manifest record with no live hosted/vendored wiring | The installed tree, unchanged | none |
390
+
| Agent: a manifest record with no live hosted/vendored wiring | The installed tree, unchanged. **Every** installed copy the crawler finds for the purl (npm nests duplicates of one `name@version`) must hash to the patched bytes, as `apply` patches every copy. One unpatched copy omits the purl with that copy's tag (`not_applied` / `hash_mismatch`). | none |
391
391
392
392
**Liveness gates.** These gates run before hashing, and `--no-verify` / `--vex-no-verify` skips only the hashing, never the gates:
0 commit comments